logo

Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data

ID: ea8535af-3f3e-5cab-ab46-e98deb66a23c

STIX ID: report--ea8535af-3f3e-5cab-ab46-e98deb66a23c

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-08

Date Updated: 2026-07-21

Author: Divya

...
...

A critical vulnerability in Google Dialogflow CX’s Playbooks Code Blocks (named “Rogue Agent” by researchers) allowed attackers with a single permission to inject Python into a shared Cloud Run environment, bypass VPC Service Controls, access conversation logs and metadata, perform stealthy data exfiltration and C2, and retrieve service account tokens via IMDS; Google issued mitigations in April 2026 and fully remediated the issue by June 2026 with no evidence of active exploitation reported prior to disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.